Red Hat Security Advisory: Red Hat OpenShift Workload Availability Operator v0.7.1 security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-25681 — golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting CVE-2026-27136 — golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass CVE-2026-33811 — net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME CVE-2026-33814 — net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame CVE-2026-39820 — net/mail: golang: Go net/mail: Denial of Service via crafted email inputs CVE-2026-39821 — golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVE-2026-42499 — net/mail: golang: net/mail: Denial of Service via pathological email address parsing
🎯 Affected products6
- Red Hat OpenShift Workload Availability 0.7
- registry.redhat.io/workload-availability/machine-deletion-remediation-operator-bundle@sha256:d3ef7d11ec2b62962e8d582587d19dc3295f8265d9bf0b0975742c5d6d810e3d_amd64 as a component of Red Hat OpenShift Workload Availability 0.7
- registry.redhat.io/workload-availability/machine-deletion-remediation-rhel9-operator@sha256:2a0dccb5cc796fe6d02a28571233b584576e2b5874ee958a161d06f0c74d8f99_s390x as a component of Red Hat OpenShift Workload Availability 0.7
- registry.redhat.io/workload-availability/machine-deletion-remediation-rhel9-operator@sha256:60f6304080ea8c80b00150595f771a050918789b3d8458db355d656b62891d68_arm64 as a component of Red Hat OpenShift Workload Availability 0.7
- registry.redhat.io/workload-availability/machine-deletion-remediation-rhel9-operator@sha256:66d3d2c1e0074ed2c9a03024a534173208adc3ab615f0b19f12296c1faf2b4aa_amd64 as a component of Red Hat OpenShift Workload Availability 0.7
- registry.redhat.io/workload-availability/machine-deletion-remediation-rhel9-operator@sha256:d2c6bf317539bb5cfae5ecf1467edcccad32f27edfa7f9fbd57314e20ecb23d7_ppc64le as a component of Red Hat OpenShift Workload Availability 0.7
✅ Remediation
For more information on the RHWA 4.22-0 release, see https://docs.redhat.com/en/documentation/workload_availability_for_red_hat_openshift/4.22-0 Workaround: To mitigate this flaw, applications processing untrusted HTML input must implement strict input sanitization and ensure all output is properly encoded before rendering. Deploying a comprehensive Content Security Policy (CSP) can restrict script execution, further reducing the attack surface. Administrators should review application configurations to ensure adequate protection against XSS. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, applications can be configured to use the pure Go DNS resolver instead of the `cgo` DNS resolver. This can be achieved by setting the `GODEBUG` environment variable to `netdns=go`. For example, to run a Go application with this mitigation: `GODEBUG=netdns=go /path/to/your/go/application`. This change may require restarting affected applications or services to take effect. Users should verify that this change does not negatively impact DNS resolution for their specific application environment. Workaround: Upgrade to a fixed golang.org/x/net release that includes the idna correction, via updated golang or dependent package rebuilds.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:54285
- externalhttps://access.redhat.com/security/cve/CVE-2026-25681
- externalhttps://access.redhat.com/security/cve/CVE-2026-27136
- externalhttps://access.redhat.com/security/cve/CVE-2026-33811
- externalhttps://access.redhat.com/security/cve/CVE-2026-33814
- externalhttps://access.redhat.com/security/cve/CVE-2026-39820
- externalhttps://access.redhat.com/security/cve/CVE-2026-39821
- externalhttps://access.redhat.com/security/cve/CVE-2026-42499
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_54285.json